CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 940
Comments: 25
block bottom
spacer spacer PIRT Squad

Fried Phish(TM)

Phishing Incident Reporting and Termination (PIRT) Squad(SM)

A global phishing termination and intelligence system operated by CastleCops. Become a PIRT Squad terminator by reporting phish today!

[ How-To / FAQ ]

Fried Phish -> Confirmed Phish | Terminated Phish


status: terminated

HTTP Response
19 May, 2008
10:00:24
HTTP/1.1 302 Found
ID829719 (termination link)
TitleUMB
Entry
PIRT Squad
Reporter
Submitted anonymously thru the web, or sent to pirt (at) castlecops (dot) com.
Timestamp16 May, 2008 @ 10:13:56
Topic ID221856 - Read/respond to PIRT commentary.
Handler Note:
16 May, 2008
20:54:00
hendomatic: Phish was active at time of investigation
Handler Note:
16 May, 2008
20:59:12
hendomatic: View CIDR AS1659 Report: http://www.cidr-report.org/cgi-bin/as-report?as=1659

"1659 | TW | apnic | 2002-08-01 | ERX-TANET-ASN1 Tiawan Academic Network (TANet) Information Center"

Handler Note:
16 May, 2008
20:59:13
hendomatic: Extended information for AS1659:
State/Province:
Country: tw
Responsible Domain: moe.edu.tw
Abuse Email: abuse@moe.edu.tw
Handler Note:
16 May, 2008
21:01:11
hendomatic: Consumed following related reports:

[830234] http://srvanti.must.edu.tw:10010
Handler Note:
16 May, 2008
21:04:13
hendomatic: Generated and sent email phish alert to respective parties.
Handler Note:
17 May, 2008
12:26:28
hendomatic: Consumed following related reports:

[830270] http://srvanti.must.edu.tw:10010/www.umb.com/Personal/
Handler Note:
19 May, 2008
19:32:55
hendomatic: Server hosting phish does not respond to ping or URL request.
TW Cert responded.
Fetched URLs
Slaves830234, 830270,

Report for at 16 May, 2008 @ 09:57:17


fetched page

at 16 May, 2008 @ 09:57:24
MD5 Fingerprint: 951c1a058f0aa632062ef95bd001283c
SHA1 Fingerprint: 7c108f1320e45fa31a9e2aa52f541b6ec96ec9e0

fetched page

at 16 May, 2008 @ 20:50:28
MD5 Fingerprint: d41d8cd98f00b204e9800998ecf8427e
SHA1 Fingerprint: da39a3ee5e6b4b0d3255bfef95601890afd80709